When deploying .NET applications or ASP.NET web sites to a server via Visual Studio Web Deploy, you may encounter deployment failures caused by untrusted or self-signed SSL/TLS certificates on the destination server.
If your server uses a self-signed certificate or an internal SSL configuration for management ports, Visual Studio will block the deployment connection by default to prevent potential security risks.
You can resolve this issue by configuring Visual Studio to accept untrusted certificates during the deployment process.
Method 1: Enable Untrusted Certificates via Visual Studio GUI
If you manage your deployment settings through Visual Studio’s user interface, follow these steps:
-
Open Your Project: Launch Visual Studio and open the project solution you wish to deploy.
-
Access Publish Settings: Select the Publish tab for your project and locate your active publish profile configuration.
-
Edit Settings: Click on Configure (or Settings depending on your Visual Studio version) to open the profile settings dialog.
-
Modify Connection Rules: Navigate to the Settings or Advanced section within the configuration menu.
-
Enable the Setting: Locate and check the box labeled "Allow untrusted certificate".
-
Save & Deploy: Save your settings and attempt to publish your project again.
Method 2: Configure the .pubxml File Directly (Advanced)
If you prefer editing configuration files directly, or if you are managing deployment profiles in a source-controlled repository, you can update the .pubxml file manually.
-
Locate the Profile File: In Visual Studio’s Solution Explorer, navigate to:
PlaintextProperties/PublishProfiles/ -
Open the File: Open the
.pubxmlfile corresponding to your deployment environment (e.g.,Production.pubxmlorStaging.pubxml). -
Add the Configuration Tag: Inside the primary
<PropertyGroup>block, insert the<AllowUntrustedCertificate>tag and set its value toTrue:
<PropertyGroup>
<AllowUntrustedCertificate>True</AllowUntrustedCertificate>
</PropertyGroup>
-
Save the File: Save your changes and re-run your publish profile.
Best Practices & Security Note
-
Testing & Staging Environments: Enabling
<AllowUntrustedCertificate>True</AllowUntrustedCertificate>is ideal for local development, staging, or internal web servers where temporary or self-signed SSL certificates are used. -
Production Environments: For live production servers, it is strongly recommended to secure your Web Deploy endpoint with a valid, trusted SSL/TLS certificate (such as a free Let's Encrypt certificate) rather than bypassing certificate validation permanently.
Need Further Assistance?
If you continue to experience deployment failures or routing issues when publishing to your server environment, reach out to our local Australian technical support team. Log into your dashboard to open a ticket directly with our engineering team.